COMPLIANCE PRICING
Menu

TRACK: BUYING AND BUDGETING · GUIDE 10 OF 10

Where the penetration test sits in the budget

Short answer

Two vendors in our census tie a penetration test to their offer: Scytale bundles one in Build DFY (web app, black box) and Build Stronger (gray box), and Thoropass runs pen testing on its platform. The other five pricing pages list no pen test, so budget it as a separate purchase there.

By The Cost Desk, Compliance Pricing · Published 2026-06-16 · Updated 2026-09-29 · 2 min read

A penetration test is a controlled attack on your systems by testers who report what they could exploit. It is a different service from compliance automation, but it often lands in the same budget, because customers ask for pen test results in security reviews and many compliance programs include regular testing.

Who bundles one

  • Scytale: Build DFY lists "Pen Test: Web App, Black Box" and Build Stronger lists "Pen Test: Gray Box". Scytale describes pen testing inside its platform: scoping with a pen test expert, reports, Jira tickets and retests.
  • Thoropass: its home page lists penetration testing and vulnerability scanning as part of the platform, and certified ASV scans for PCI DSS.
  • Vanta, Drata, Secureframe, Sprinto and Scrut: no pen test is listed on the pricing pages we read.

Black box, gray box and scope

  • Black box: testers start with no inside knowledge, like an outside attacker.
  • Gray box: testers get partial knowledge or access, such as a user account or architecture notes, which lets them go deeper in the same time.
  • Scope: which systems are tested (a web app, an API, a cloud environment, a network). Scope decides most of a pen test's cost.

When comparing a bundled pen test with a separate one, compare the same type and scope. A black-box web app test and a gray-box test of a whole environment are different purchases.

Do you need one?

That depends on your auditor's expectations and your customers' questions. The vendor pages we read do not say a pen test is mandatory for SOC 2, and this site does not either. Ask your auditor what testing evidence they expect, and check your customers' security questionnaires, which often ask when you last had a pen test.

Bundled or separate?

A bundle is convenient: one contract, findings tracked where your compliance work lives. A separate test lets you pick the testing firm and scope. Either way, ask for the pen test portion of a bundle to be itemized so you can compare it with a direct quote.

Questions for your quote

  • What type (black box or gray box) and what scope does the included test cover?
  • Is a retest after fixes included?
  • How often is the test repeated during the term?
  • Who performs it, and what report do we receive?

The takeaway

Decide type and scope first, then compare bundled and separate prices on the same scope. Set "Need a penetration test" to Yes in the calculator to see which plans list one.

Next guide: What drives compliance automation pricing